Step 1: The management’s toolbox
An effective cyber defence is anchored in top management. In essence, it is about the
top management overseeing cyber and information security on equal footing with
areas such as finance, HR, development and research. Similarly, the handling of
personal information has become an area that requires top management oversight.
Even the very best intentions regarding an effective cyber defence will fail without
anchoring at the top management level.
It is important for a leader to understand the cyber threat. It is equally important to
realize that this threat is an underlying condition for all Danish organizations. The top
management must take ownership of the organization’s cyber and information security
objectives and strategies. The policies, procedures and guidelines used to manage
cyber and information security within the entire organization must reflect these
objectives and strategies.
The top management must prioritize the establishment of repeatable processes
designed to support the organization’s cyber and information security strategy.
Without established and documented processes, there is a risk of handling cyber and
information security risks on an ad hoc basis with an over dependency on few key
personnel. The top management must ensure that the established processes are
regularly controlled and improved in order to ensure their efficiency.
When organizations develop and implement new infrastructure, systems and
applications. There is an also a particularly important juncture in which to improve
cyber and information security; that is The top management must ensure a formal
process for factoring cyber and information security considerations from the start of
new projects.
In general, the top management must prioritize and oversee cyber and information
security across the organization. In this context, it is important for the top
management to ensure that the right skills are available either on premise or off
premise, in the form of external consultants or advisers.
The formulation of objectives and strategies, prioritization of resources, establishment
of repeatable processes, and regular follow-ups are the management’s most important
tools when overseeing cyber and information security.
We recommend that the top management asks itself eight
questions and asks its organization sixteen questions. The
answers to these questions will give the top management
an idea of how the organization works with cyber and
information security.
4